Missing Authentication for Critical Function in KACE Systems Management Appliance (SMA) - CVE-2025-32978
Published: April 24, 2026
KACE Systems Management Appliance (SMA)
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing authentication for a critical function in the license renewal web interface when handling license replacement requests. A remote attacker can submit a crafted license replacement request to cause a denial of service.
This can disrupt administrative functions by replacing a valid license with an expired or trial license.